BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

3 BIOCs match the current filters. technique: T1588 ✕

Download CSV Show ATT&CK heatmap
  • Simulation activity by AttackIQ Informational Execution

    Simulation activity performed by AttackIQ agent.

    Indicator:

    File action type = all Process initiator cmd = *AttackIQ*attack_graph.py*

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Simulation activity by Cymulate Informational Execution

    Simulation activity performed by Cymulate agent.

    Indicator:

    File action type = all Process initiator cmd =~ .*(\\ProgramData\\Cymulate\\Agent\\Temp\\cfd_|\\Cymulate\\EDR_Attacks\\).* AND initiated by =~ (cfd|CymulateEDRScenarioExecutor)\.exe

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Simulation activity by SafeBreach Informational Execution

    Simulation activity performed by a SafeBreach agent.

    Indicator:

    File action type = all Process initiated by = sbsimulation_sb_*.exe

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23